[Paper Review] Twisted Gabidulin Codes in the GPT Cryptosystem
This paper proposes a subfamily of twisted Gabidulin codes for use in the GPT code-based public-key cryptosystem, demonstrating resistance to Overbeck's structural attack. The resulting key sizes are significantly smaller than in the original McEliece system and slightly smaller than in Loidreau's unbroken GPT variant, offering improved efficiency for rank-metric cryptography with comparable security levels.
In this paper, we investigate twisted Gabidulin codes in the GPT code-based public-key cryptosystem. We show that Overbeck's attack is not feasible for a subfamily of twisted Gabidulin codes. The resulting key sizes are significantly lower than in the original McEliece system and also slightly smaller than in Loidreau's unbroken GPT variant.
Motivation & Objective
- To investigate the security of twisted Gabidulin codes in the GPT code-based public-key cryptosystem.
- To determine whether Overbeck's attack remains feasible against a subfamily of twisted Gabidulin codes.
- To evaluate the resulting key sizes and compare them with existing rank-metric and Hamming-metric code-based cryptosystems.
- To assess the potential of twisted Gabidulin codes as a foundation for efficient, secure post-quantum encryption.
Proposed method
- The authors analyze a subfamily of twisted Gabidulin codes defined by adding a monomial to Gabidulin code evaluation polynomials with a carefully chosen coefficient to preserve maximum rank distance (MRD) properties.
- They apply Overbeck's attack framework to the GPT system using twisted Gabidulin codes and show that the attack fails due to structural invariants preserved in the code family.
- The security is evaluated against syndrome decoding, Gibson's attack, and an exponential-time attack based on the $q$-sum of the code, with work factor $W_{\mathrm{Exp-Att}} \approx q^{m\ell}$.
- Key size comparisons are performed using parameters that achieve target security levels of $2^{80}$, $2^{130}$, and $2^{260}$, with results tabulated for McEliece, Loidreau, QC-MDPC, and the proposed twisted GPT system.
- The $q$-sum dimension of the code is analyzed to assess distinguisher risks, though no explicit attack is found to exploit this property.
Experimental results
Research questions
- RQ1Can Overbeck's attack be successfully mounted against the GPT cryptosystem when using a subfamily of twisted Gabidulin codes?
- RQ2What are the resulting key sizes for twisted Gabidulin codes in the GPT system compared to McEliece and Loidreau's schemes at equivalent security levels?
- RQ3Does the low $q$-sum dimension of twisted Gabidulin codes with small $\ell$ introduce a practical vulnerability despite resisting known structural attacks?
- RQ4How does the security of the twisted GPT system compare to other code-based systems like QC-MDPC under the same work factor assumptions?
Key findings
- Overbeck's attack is not feasible against the proposed subfamily of twisted Gabidulin codes, providing a strong structural resistance to this major class of attacks.
- The key size for the twisted GPT system is 3.28 KB at a 80-bit security level, which is smaller than McEliece's 78.98 KB and comparable to Loidreau's 3.60 KB.
- At a 128-bit security level, the key size is 6.93 KB, which is still significantly smaller than McEliece's 242.00 KB and larger than QC-MDPC's 0.60 KB.
- The security level is dominated by the syndrome decoding attack from [11], which gives the smallest work factor across all tested parameters.
- Despite a distinguisher based on low $q$-sum dimension for small $\ell$, no explicit attack is known to exploit this property, leaving the system unbroken to date.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.